ClickFix: the fake CAPTCHA that runs a script hidden in your browser cache
A website shows a "Confirm you're not a robot" box, or a "loading error — click to fix" message, and asks you to press Win+R, paste a command, and hit Enter. The person doesn't download or install anything by hand, so it doesn't feel dangerous. This is the ClickFix scheme, and on October 6 Microsoft Threat Intelligence described a new variant that bypasses protection at the exact point where a suspicious command used to be easy to spot.
Who this affects
Any employee with a browser and internet access — not just IT staff. The victim doesn't install software or download a file with an obvious name like virus.exe: they simply search Google for a fix to some problem, land on a fake page, and follow a couple of clicks and an Enter key. According to CrowdStrike, fake-CAPTCHA attacks grew by 563% in 2025 — this scheme is becoming common, and anyone can run into it.
How it works, in plain terms
In the classic ClickFix attack, the website makes the victim paste a command into the Run box that downloads malicious code from an external server. That long, suspicious-looking command was relatively easy to notice or block with security filters.
The new variant is more cunning. The malicious script is pre-loaded into the victim's browser cache ahead of time, disguised as an ordinary picture (PNG). The command the victim is asked to paste into Run is short and doesn't look suspicious: it downloads nothing new — it just pulls the file that's already sitting in the browser cache, copies it into a temporary folder, and launches it with a built-in Windows component. This is how the attack gets around the Run dialog's limit on command length (roughly 260 characters), a limit that previously helped flag a malicious command just by its length.
Once running, the script collects information about the computer using standard Windows tools, fetches another script from an external server, and then disguises itself as a system process so neither antivirus software nor the user notices it. The end goal is the passwords and browser data stored on the device.
What to do today
- Agree with your team on one rule: never paste commands into Run (Win+R), PowerShell, or a terminal because a website told you to — even if the page looks official and claims it's "for verification" or "to fix an error."
- Make the rule simple: a real CAPTCHA never asks you to press Win+R and paste a command. If a site asks for that, just close the tab.
- Warn the people most likely to run into this first — anyone who regularly googles error messages or downloads files from unfamiliar sites: accounting, marketing, sales, not only IT.
- Make sure work computers have antivirus software with up-to-date definitions and browsers that are kept current — part of this attack gets blocked at that level already.
- If someone has already pasted a command like this, don't wait for symptoms to appear: change passwords (starting with email and online banking) and contact whoever manages your IT.
If an outside provider handles your IT
Ask them:
- Do the computers have protection that blocks scripts from running off a command pasted from the clipboard?
- Have you given staff even a short heads-up about ClickFix and fake CAPTCHAs?
- How quickly would you notice an unfamiliar process on a machine disguising itself as a system process?
If the answers are vague, that's a good reason for an independent check.
Want to know how well-protected your company's computers are? Run a free check on your domain on our site (domain check) or message us on Telegram @NextGenITCY or at info@nextgenit.com.cy — we'll take a look at what can be improved.
Sources: The Hacker News